×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research: The new NGate is hidden in an NFC payment app, probably developed with AI

Customer Press Room

ESET Research: The new NGate is hidden in an NFC payment app, probably developed with AI

by Grandangolo Communications / Tuesday, 21 April 2026 / Published in Eset

ESET researchers have identified a new variant of NGate malware that exploits the legitimate HandyPay app on Android. Spread since November 2025, it affects users in Brazil via fake sites (lotteries and Google Play). Probable use of GenAI to infect the app and spread the trojan

ESET Research has discovered a new variant of the NGate malware family that exploits a legitimate Android application called HandyPay, rather than the previously used NFCGate tool. The attackers took the app, used to transmit NFC (Near Field Communication) data, and modified it by inserting malicious code that appears to have been generated by AI. As in previous NGate variants, the malicious code allows attackers to transfer NFC data from the victim's payment card to their device and use it for contactless withdrawals from ATMs and unauthorized payments. Furthermore, the code is capable of capturing victims' payment card PINs and sending them to the operators' command and control server. The threat targets users in Brazil but NFC-based attacks are expanding to new regions.

The malicious code used to infect HandyPay with a Trojan appears to have been created with the help of generative AI (GenAI) tools. Specifically, the malware logs contain an emoji typical of AI-generated texts, suggesting that built-in Large Language Models (LLMs) were involved in generating or modifying the code, although there is no definitive evidence yet. This is part of a broader trend in which GenAI would reduce barriers to entry for cybercriminals, allowing hackers with limited technical expertise to produce working malware.

ESET Research believes that the distribution campaign of the Trojan-infected HandyPay began around November 2025 and is still active. It should also be noted that the maliciously modified version of HandyPay was never available on the official Google Play Store. As a partner of the App Defense Alliance, ESET shared its findings with Google. ESET has also contacted the developers of HandyPay to warn them about malicious use of their application.

The increase in NFC threats has led to a consolidation of the ecosystem that supports them. Early NGate attacks used the open source NFCGate utility to facilitate NFC data transfer. Since then, several versions of malware-as-a-service (MaaS) with similar functionality have been made available to the public. However, in this campaign the attackers decided to opt for their own solution, applying a malicious patch to an existing app, the HandyPay one.

«Why did the authors of this campaign decide to infect the HandyPay app with a Trojan instead of using an established solution for NFC data transfer? The answer is simple: money. Subscription costs for existing MaaS kits run into the hundreds of dollars: NFU Pay advertises its product at nearly $400 per month, while TX-NFC offers it for around $500 per month. On the other hand, the legitimate HandyPay app is significantly cheaper, requiring a donation of just €9.99 per month, if not even less. Besides the price, HandyPay “does not ask for any permission other than to be set as the default payment app, thus helping the threat actors not to arouse suspicion,” says ESET researcher Lukáš Štefanko, who spotted the new NGate variant in the infected NFC payment app.

The first new NGate champion is released via a website that presents itself as Rio de Prêmios, a lottery operated by the Rio de Janeiro state lottery (Loterj). The second NGate sample is distributed via a fake Google Play webpage in the form of an app called Proteção Cartão (Card Protection). Both websites resided on the same domain, which strongly suggests the existence of a single threat actor. The malware uses the HandyPay service to forward NFC card data to a device controlled by the attacker. In addition to transmitting NFC data, the malicious code also steals payment card PINs, allowing the attacker to use the victim's payment card data to withdraw cash from ATMs.

About Grandangolo Communications

What you can read next

ESET Threat Intelligence data feeds improve visibility for users of the Microsoft Sentinel SIEM/SOAR platform
ESET Research: Toolkit used by ransomware group Embargo discovered that disables security solutions
ESET releases the latest APT report: the pro-Cinese groups expand the range of action, Iran intensifies diplomatic espionage

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP